S3Proxy Filesystem Backends Path Traversal Vulnerability
Vulnerability
A path traversal vulnerability has been identified in S3Proxy's filesystem and filesystem-nio2 storage backends, allowing authenticated users to unintentionally access local files. This issue affects S3Proxy versions prior to 2.6.0 and has been patched in version 2.6.0.
Impact
Exploitation of this vulnerability could lead to unauthorized access to local files on the server, potentially exposing sensitive information to authenticated users.
Reproduction
The vulnerability can be reproduced by uploading a file with a name that includes path traversal sequences, such as '../evil.txt', to a container in the affected storage backend. The file will be accessible through the S3 API, exposing local files to authenticated users.
Remediation
Users are advised to upgrade to S3Proxy version 2.6.0 or later.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
